Memory Corruption in Unbound by NLnet Labs
CVE-2026-52863
What is CVE-2026-52863?
The vulnerability in Unbound versions 1.25.0 to 1.25.1 stems from an issue in the interaction between the 'respip' and 'dns64' modules, which can produce a shallow copy of the view name. This may lead to potential memory corruption if the original view owner is removed during high load conditions. The issue arises when Unbound is performing under pressure while configured with specific modules alongside 'access-control-view'. In scenarios where the jostle logic becomes active and starts discarding slow queries, incorrect handling may result in memory corruption. Although the likelihood of a crash is low due to dependence on the memory allocator, configurations utilizing debug memory builds (such as ASAN) may lead to server termination upon memory corruption detection.
Affected Version(s)
Unbound 1.25.0 < 1.25.2
